Tag: supply-chain
-
The Mystery of ‘Jia Tan,’ the XZ Backdoor Mastermind
The thwarted XZ Utils supply chain attack was years in the making. Now, clues suggest nation-state hackers were behind the persona that inserted the m… First seen on wired.com Jump to article: www.wired.com/story/jia-tan-xz-backdoor/
-
Synopsys Introduces Latest Solution for Comprehensive Security Across Software Supply Chains
Synopsys has introduced Black Duck® Supply Chain Edition, a novel software composition analysis (SCA) solution. This offering aids organisations in mi… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/04/09/synopsys-introduces-latest-solution-for-comprehensive-security-across-software-supply-chains
-
New Tool Aims to Simplify and Streamline SBOM Adoption
OpenSSF Partners With DHS and CISA to Launch Global Software Supply Chain Project. OpenSSF launched a new tool Tuesday in partnership with the Departm… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/new-tool-aims-to-simplify-streamline-sbom-adoption-a-24872
-
SoftwareChain-Angriff: xz-utils-Backdoor gefährdet Linux-Systeme
Eine Supply-Chain-Attacke über xz-utils sorgt seit einigen Tagen für Aufregung in der IT-Security-Szene. Der Angriff wurde offenbar von langer Hand ge… First seen on csoonline.com Jump to article: www.csoonline.com/de/a/xz-utils-backdoor-gefaehrdet-linux-systeme
-
Sisense Breach Highlights Rise in Major Supply Chain Attacks
Experts Warn of Growing Threat From Supply Chain Attacks After High-Profile Breach. Cybersecurity experts are sounding the alarm over a rise in supply… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/sisense-breach-highlights-rise-in-major-supply-chain-attacks-a-24864
-
6-year-old Lighttpd Flaw Impacts Intel And Lenovo Servers
The software supply chain is filled with various challenges, such as untracked security vulnerabilities in open-source components and inconsistent upd… First seen on gbhackers.com Jump to article: gbhackers.com/lighttpd-flaw-intel-lenovo-servers/
-
Tips for Securing the Software Supply Chain
Industry experts share how to implement comprehensive security strategies necessary to secure the software supply chain in Dark Reading’s latest Tech … First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/tips-for-securing-the-software-supply-chain
-
Home Depot Hammered by Supply Chain Data Breach
First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/home-depot-hammered-by-supply-chain-data-breach
-
Sisense customers told to reset credentials amid supply chain attack fears
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/sisense-customers-told-to-reset-credentials-amid-supply-chain-attack-fears
-
ISMG Editors: Unpacking the Change Healthcare Attack Saga
Also: Positive Cyber Market Trends, AI Threats to Supply Chain Security. In the latest weekly update, four ISMG editors discussed the unending twists … First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ismg-editors-unpacking-change-healthcare-attack-saga-a-24848
-
Software supply chain risk mitigation sought by new Synopsys solution
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/software-supply-chain-risk-mitigation-sought-by-new-synopsys-solution
-
Sisense Data Breach Triggers CISA Alert and Urgent Calls for Credential Resets
The US government issues a red-alert for what appears to be a massive supply chain breach at Sisense, a company that sells big-data analytics tools. T… First seen on securityweek.com Jump to article: www.securityweek.com/sisense-data-breach-triggers-cisa-alert-and-urgent-calls-for-credential-resets/
-
XZ-Utils-Vorfall Open Source als SoftwareChain-Falle
Die Entwicklung von Open-Source wird oftmals angepriesen, da die Projekte öffentlich zugänglich sind und somit von Unabhängigen überprüft werden könne… First seen on netzpalaver.de Jump to article: netzpalaver.de/2024/04/08/xz-utils-vorfall-open-source-als-software-supply-chain-falle/
-
XZ Utils Supply Chain Attack: A Threat Actor Spent Two Years to Implement a Linux Backdoor
First seen on techrepublic.com Jump to article: www.techrepublic.com/article/xz-backdoor-linux/
-
Breach Roundup: Sisense Supply Chain Attack
Also: A Romanian Botnet and Alcohol Counselor Monument Settles with US FTC Over Ads. This week, Sisense supply chain attack, a likely Romanian botnet,… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-sisense-supply-chain-attack-a-24841
-
Supply chain SNAFU causes Intel and others to ship hackable hardware for 5 years
First seen on arstechnica.com Jump to article: arstechnica.com/
-
Vulnerabilities Exposed Hugging Face to AI Supply Chain Attacks
Wiz.io, known for its cloud security expertise, and Hugging Face, a leader in open-source AI tools, are combining their knowledge to develop solutions… First seen on hackread.com Jump to article: www.hackread.com/hugging-face-vulnerability-ai-supply-chain-attack/
-
Eclypsium’s Digital Supply Chain Security Platform Releases AI-Assisted Binary Analysis Engine
New Eclypsium Automata replicates expert security researchers’ knowledge and leverages advances in machine learning to discover threats, backdoors, an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/eclypsiums-digital-supply-chain-security-platform-releases-ai-assisted-binary-analysis-engine/
-
Open-Source Foundations Join Forces on Digital Supply Chain
Europe’s Cyber Resilience Act Pressures Open-Source Foundations and Manufacturers. Foundations housing seven large open-source projects are banding to… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/open-source-foundations-join-forces-on-digital-supply-chain-a-24804
-
XZ Utils Backdoor Implanted in Carefully Executed, Multiyear Supply Chain Attack
First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/xz-utils-backdoor-implanted-in-intricate-multi-year-supply-chain-attack
-
Die Cybersicherheit von Deutschlands Top 100 Unternehmen – Risiken in der Lieferkette im digitalen Ökosystem
First seen on security-insider.de Jump to article: www.security-insider.de/cybersecurity-report-sicherheitsverletzungen-durch-dritte-2023-a-10968662af0dfc4e66f7f924dcacbf46/
-
Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others
Unidentified adversaries orchestrated a sophisticated attack campaign that has impacted several individual developers as well as the GitHub organizati… First seen on thehackernews.com Jump to article: thehackernews.com/2024/03/hackers-hijack-github-accounts-in.html
-
XZ and the Threats to the Digital Supply Chain
The discovery of the backdoor in xz utils compression software last week has shone a spotlight on the threats to the digital supply chain. Wired has a… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/xz-and-the-threats-to-the-digital-supply-chain/
-
Trusted Contributor Plants Sophisticated Backdoor in Critical Open-Source Library
A backdoor in XZ Utils, a widely used file-compressing software in Linux systems, could have led to a critical supply chain attack had a Microsoft res… First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/backdoor-xz-utils-linux-open-source/
-
New XZ backdoor scanner detects implant in any Linux binary
Firmware security firm Binarly has released a free online scanner to detect Linux executables impacted by the XZ Utils supply chain attack, tracked as… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-xz-backdoor-scanner-detects-implant-in-any-linux-binary/
-
The Open-Source Backdoor That Almost Compromised SSH
The open-source world narrowly escaped a sophisticated supply-chain attack that could have compromised countless systems. A stark reminder of the nece… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/the-open-source-backdoor-that-almost-compromised-ssh/
-
Top 5 Vulnerabilities for March 2024: A Closer Look at the XZ Utils Supply Chain Attack
March may have roared in like a lion, but for cybersecurity professionals, it was more like a backdoor sneaking into a critical utility. This month, w… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/04/top-5-vulnerabilities-for-march-2024-a-closer-look-at-the-xz-utils-supply-chain-attack/
-
GitHub Developers Hit in Complex Supply Chain Cyberattack
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/github-developers-hit-in-complex-supply-chain-cyberattack
-
170K+ Python Developers GitHub Accounts Hacked in Supply Chain Attack
Over 170,000 users have fallen victim to a meticulously orchestrated scheme exploiting the Python software supply chain. The Checkmarx Research team h… First seen on gbhackers.com Jump to article: gbhackers.com/170k-user-accounts-hacked/
-
Complex Supply Chain Attack Targets GitHub Developers
Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/

